Commit Graph
22 Commits
Author SHA1 Message Date
User 7a65fc80a2 fix(deploy): validate session migrator TLS mode 2026-07-16 19:07:53 +02:00
User cadc4c6947 docs(deploy): document user-owned session cutover 2026-07-16 19:02:58 +02:00
User 6dbf93fff9 feat: harden runtime readiness and session workflow 2026-07-14 10:27:25 +02:00
User 664d392859 fix: remove verbose tool logs from UI + symlink config/tht.yaml
Two fixes:
1. Revert tool_execution_* forwarding: these cluttered the UI with raw
   bash/read output the user never asked for. Only text_delta, system_event
   and ui_request are forwarded, as before.

2. tht ignores THT_CONFIG env var and always looks for config/tht.yaml
   relative to CWD. Create a symlink so the PI agent can run tht commands
   without -c flag.
2026-07-13 00:29:28 +02:00
User ac333f99ac fix(docker): chown .pi to thoth so Pi locks survive rebuilds 2026-07-13 00:14:37 +02:00
User 122cbfd50d fix(docker): post-merge fixes for codex backend compatibility
- restore COPY harness/ (perso durante edit) -> /app/harness esiste
- cp workflow.yaml in site-packages: tht lo carica module-relative
  (parent.parent del package); non-editable install non lo includeva
  -> session show 500 (FileNotFoundError). pip install -e non accettato da pip.
- cd /app/harness && pip install . : pip 26.1.2 rifiuta il path bare /app/harness
- compose: THT_MODEL_API_KEY_FILE per buildPiChildEnv (codex) -> session create
  prima 500 'model provider credential is unavailable'
Verificato: session show 200 (phase 1), create 200, Pi+model+SSE OK.
2026-07-12 21:30:49 +02:00
User 2bd2f72356 Merge origin/codex/portable-deployment into feat/docker-local-deploy
Unisce gli internals di Codex (secret-bundle, provider-credentials, auth upstream,
security hardening, CI multiarch) mantenendo le fix portal-specific:
- backend: configPath da THT_CONFIG (fix sessioni) + dataRoot di Codex; authMode 'upstream'
- Docker/compose: TENUTO il mio (verificato live: omics_network+alias, env_file, pi npm-g)
  perche' il compose/Dockerfile/entrypoint di Codex sono accoppiati al suo modello
  secret-bundle (tht doctor inesistente, secret-policy.sh). Adottabile in futuro.
- config.test.ts: preso Codex (superset)
Verificato: tsc clean, 132/132 vitest.
2026-07-12 21:13:20 +02:00
marcopan 7628eaa579 fix(docker): run real questions through trusted Pi gate 2026-07-12 19:20:10 +02:00
User 5f6647e77a fix(entrypoint): restore server case (lost during doctor->check refactor)
Il caso 'server)' era stato eliminato inavvertitamente: CMD [server]
cadeva nel *) exec $@ -> 'server: not found' (exit 127).
Smoke standalone ora verde: health + config check + db ping (read-only).
2026-07-12 17:17:24 +02:00
User 67d030b24d feat(deploy): docker images, compose, roles SQL, local workspace
- core.Dockerfile: python:3.12-slim + node 22 copied (same bookworm glibc), non-root, tht+pi
- frontend.Dockerfile: vite build (env-driven base/assetsDir) + nginx-unprivileged
- compose.yaml (embedded, omics_network ext, zero host ports) + docker-compose.dev.yml (standalone)
- deploy/sql: thoth_dwh_reader (ro) + thoth_vector_rw (rw) roles
- deploy/thothii.env.example + harness/workspaces/local.yaml (direct DWH+vector, 5438)
- scripts/docker-smoke.sh; .dockerignore; gitignore deploy secrets
- verified: both images build, core health {ok}, config check validates local.yaml
2026-07-12 16:49:03 +02:00
marcopan f67d2c97d8 fix(security): reject invalid optional bundle values 2026-07-12 11:53:15 +02:00
marcopan 449a333365 fix(security): validate bundle and clean runtime secrets 2026-07-12 11:52:02 +02:00
marcopan 70a19f290d feat(compose): use one secret bundle for local services 2026-07-12 11:30:43 +02:00
marcopan e40a9d9a56 fix(backend): inject provider credentials from file 2026-07-12 07:53:22 +02:00
marcopan 4028ef7821 feat(preprocess): add deployment jobs and S3 source 2026-07-12 05:42:07 +02:00
marcopan 3588a7749b fix(vector): harden packaged migrations 2026-07-12 01:32:33 +02:00
marcopan ebdd3aa2c5 fix(deploy): unify backend URL policy 2026-07-12 00:54:39 +02:00
marcopan a3a266fd81 fix(deploy): close container final review 2026-07-12 00:44:39 +02:00
marcopan 715de6649b fix(docker): harden frontend runtime config 2026-07-11 22:03:24 +02:00
marcopan 3d939426b1 build(docker): add runtime-configured frontend image 2026-07-11 21:57:53 +02:00
marcopan 31023f9e7a build(docker): lock core runtime dependencies 2026-07-11 21:50:30 +02:00
marcopan 77923e501f build(docker): add core application image 2026-07-11 21:43:28 +02:00